CVE-2005-3878

PHP Doc System < 1.5.1 - Directory Traversal via Show Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-3878. PoCs published by r0t.

AI-analyzed exploit summary The provided text describes a local file inclusion vulnerability in PHP Doc System 1.5.1 and prior versions. The vulnerability arises from improper input sanitization, allowing unauthorized file access or PHP code execution via path traversal.

Description

Directory traversal vulnerability in index.php in PHP Doc System 1.5.1 and earlier allows remote attackers to access or include arbitrary files via a .. (dot dot) in the show parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by r0t · textwebappsphp
https://www.exploit-db.com/exploits/26643

The provided text describes a local file inclusion vulnerability in PHP Doc System 1.5.1 and prior versions. The vulnerability arises from improper input sanitization, allowing unauthorized file access or PHP code execution via path traversal.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: PHP Doc System <= 1.5.1
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/17745
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/15611
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/2622

Scores

EPSS 0.0258
EPSS Percentile 83.2%

Details

Status published
Products (1)
alex_king/php_doc_system < 1.5.1
Published Nov 29, 2005
Tracked Since Feb 18, 2026